Feature Recycle/Cancel bin: any user with access to the bin can see/restore/delete all the items in it

XMLWordPrintable

    • Type: Bug
    • Resolution: Unresolved
    • Priority: Medium
    • None
    • Affects Version/s: 11.13.1
    • Component/s: Features - Grid

      Issue Summary

      When accessing the Recycle/Cancel bin, user can select "All Programs" to display the items that were deleted/canceled, even the ones he is not part of the Portfolio/Program. Due to this, he is able to restore/delete items that he normally is not able to see on the grids.

      Steps to Reproduce

      1. Under Settings > Roles > Select a Role > Expand 'Solution' disable all capabilities permission
      2. Under Settings > Roles > Select a Role > Expand 'Team' disable all defects permission
      3. Navigate to the Home page and click on the Items dropdown, notice that the user doesn’t have access/view of Capabilities and defects
      4. Access the recycle bin under Stories/Features > More actions 
      5. Notice that all the item dropdown shows Capabilities and Defects and the items under it are visible and deletable/restorable for the user
      6. Notice that for some users, they can see items from other programs/portfolios/users

      Expected Results

      Recycle/Cancel bin would follow the same logic that the grids use for access to items.

      Actual Results

      Recycle/Cancel bin doesn't apply the logic of being a member of a Portfolio/Program/Have toggle permissions to see items.

      Workaround

      Currently, there is no known workaround for this behavior. A workaround will be added here when available

            Assignee:
            Don Fuller
            Reporter:
            Alessandra Garcia
            Votes:
            5 Vote for this issue
            Watchers:
            8 Start watching this issue

              Created:
              Updated: